CVE ReportsCVE-2026-33162: Authorization Bypass in Craft CMS Entry Relocation Vulnerability ID:...
Vulnerability ID: CVE-2026-33162
CVSS Score: 4.9
Published: 2026-03-24
Craft CMS versions 5.3.0 to 5.9.13 and 4.x prior to 4.17.8 contain a Missing Authorization vulnerability (CWE-862) within the Control Panel. Authenticated users with baseline administrative access can bypass intended UI restrictions to arbitrarily relocate content entries between sections without possessing the required section-specific permissions.
An authorization bypass in Craft CMS allows authenticated users with standard Control Panel access to relocate content entries across sections without proper validation. The vulnerability is patched in versions 5.9.14 and 4.17.8 by implementing explicit server-side authorization checks.
5.9.14)4.17.8)Fix Missing Authorization in EntriesController actionMoveToSection
accessCp permission.Remediation Steps:
Read the full report for CVE-2026-33162 on our website for more details including interactive diagrams and full exploit analysis.